Jump to content

Norton Power Eraser Finding Things


dvideo

Recommended Posts

Tried to go to squarespace.com today (a popular site) and mistyped the URL.

Norton Power Eraser popped up and said a large amount of outgoing traffic was detected and recommended running Power Eraser. I did and it said it fixed the registry but still lists

C:\Windows\System32\Tasks
OneDrive Standalone Update Task-S-1-5-21-2604578423-1325664717-4041599089-1001

and

C:\Windows\Tasks
CreateExplorerShellUnelevatedTask.job

as concerns. Malwarebytes Scan even with rootkit check does not detect anything.

How can I be sure I'm not infected?

Thanks.

Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.
Click Attach this file.
Click the Add reply button.
===

Please post the logs  for my review.

Wait for further instructions

Link to post
Share on other sites

Here is the information you asked for...

Log file links...

Addition.txt

FRST.txt

Also, these are the things Norton Power Eraser warned me about...

Registry error (which it said it fixed)

C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job (Not sure what's in this or if I could just delete it)

C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2604578423-1325664717-4041599089-1001 (For now I disabled this task from running)

I also see User_Feed_Synchronization-{18F9BE0A-7447-462A-B043-D03C5309F76E} but have no idea if I should be concerned.

Thanks!
 

Link to post
Share on other sites

Hi,

Run thi fix to clean all the empty registry items.

Please download the attached Fixlist.txt file to  the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Your concerned items.

C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job (Not sure what's in this or if I could just delete it)


This is the reaspn you are getting the warnong from Norton.

You are running Explorer in an Unelevated task.
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

As suggested in this article:
https://www.tenforums.com/general-support/79917-whats-createexplorershellunelevatedtask.html

You can run the task to by pass the UAC prompt.

You will have to change the CreateExplorerShellUnelevatedTask.job as suggested here.

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\Explorer.EXE /NOUACCHECK

You may want to keep the protection you have now. Your call.
=====

I also see User_Feed_Synchronization-{18F9BE0A-7447-462A-B043-D03C5309F76E} but have no idea if I should be concerned.

If you do not subscribe to any RSS feeds at all disable it.
https://answers.microsoft.com/en-us/windows/forum/windows_xp-performance/microsoft-feeds-synchronization/89ffe6c5-d690-4d17-9bab-9e959e94286e?messageId=570a436b-5a7d-46d9-9456-3001d604618b
===

Hope that helps.

Link to post
Share on other sites

  • 5 weeks later...
  • Root Admin

Due to the lack of feedback, this topic is closed to prevent others from posting here.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this topic. Other members who need assistance please start your own topic in a new thread.

Thanks

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.